CVE-2019-16667
diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands. This occurs because csrf_callback() produces a "CSRF token expired" error and a Try Again button when a CSRF token is missing.
- Affected products
- Pfsense
- Netgate Pfsense
- = 2.4.4
- Fix
- Available
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 54.5% (99th percentile)
- Weakness
- CWE-352
- NVD status
- Modified
- Published
- 2019-09-26
CVE-2019-16667 at NVD
3 known exploits for CVE-2019-16667
Proof-of-concept code and exploit modules indexed by Sploitus